generated: '2026-08-06' method: generated source: openapi/armor-accounts-openapi-original.yml, openapi/armor-agent-management-openapi-original.yml, openapi/armor-compliance-openapi-original.yml, openapi/armor-container-security-openapi-original.yml, openapi/armor-fh-auth-openapi-original.yml, openapi/armor-incident-management-openapi-original.yml, openapi/armor-infrastructure-management-openapi-original.yml, openapi/armor-log-management-openapi-original.yml, openapi/armor-mdr-public-openapi-original.yml, openapi/armor-notifications-openapi-original.yml, openapi/armor-psk-auth-openapi-original.yml, openapi/armor-v1-account-management-swagger-original.json, openapi/armor-v1-infrastructure-swagger-original.json, openapi/armor-v1-security-swagger-original.json, openapi/armor-v1-support-swagger-original.json, openapi/armor-webhooks-openapi-original.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 427 by_action_class: acting: 172 connected: 255 by_consequence: write: 161 read: 255 safety-critical: 5 physical: 6 human_in_the_loop_required: 5 operations: - path: /cloud-connections method: post operationId: getCloudConnectionsByAccountId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cloud-connection/service-types method: get operationId: getConnectionServiceTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cloud-connections/{connectionId} method: get operationId: getCloudConnectionDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /securenotes/securenotes method: get operationId: getAllSecureNotes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /securenotes/securenotes method: post operationId: createSecureNote x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /securenotes/securenotes/{id} method: get operationId: getSecureNoteById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /securenotes/securenotes/{id} method: put operationId: updateSecureNote x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /securenotes/securenotes/{id} method: delete operationId: deleteSecureNote x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /securenotes/securenotes/{id}/reveal method: get operationId: revealSecureNoteContent x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{userId}/tours method: get operationId: getTourPreferences x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{userId}/tours method: put operationId: updateTourPreferences x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /healthmonitoringstatus method: get operationId: getHealthMonitoringStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /healthmonitoringstatus/{coreInstanceId} method: get operationId: getHealthMonitoringStatusByCoreInstanceId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /trend/exclusion-list method: get operationId: getExclusionLists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /trend/exclusion-list method: post operationId: createExclusionList x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/exclusion-list/{id} method: put operationId: updateExclusionList x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/exclusion-list/{id} method: delete operationId: deleteExclusionList x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/malware-exclusion-config method: get operationId: getMalwareExclusionConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /trend/malware-exclusion-config method: post operationId: createMalwareExclusionConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/malware-exclusion-config method: put operationId: updateMalwareExclusionConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/malware-exclusion-config method: delete operationId: deleteMalwareExclusionConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /trend/malware-exclusion-config/apply method: put operationId: applyMalwareExclusionConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scheduled-tasks/details/{cid} method: get operationId: getCliResultsByCoreInstanceId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /products method: get operationId: getProducts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scheduled-tasks method: get operationId: getScheduledTasks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scheduled-tasks method: post operationId: scheduleTask x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v2/scheduled-tasks method: get operationId: getScheduledTasksPaginated x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scheduled-tasks/{id} method: get operationId: getTaskDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scheduled-tasks/{id} method: post operationId: updateTask x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags method: get operationId: getAllTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tags/resources method: post operationId: getResourcesByTag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/{resourceid} method: get operationId: getTagsByResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tags/{resourceid} method: post operationId: createTag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/lock/{resourceid} method: post operationId: createLockedTag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/delete/lock/{resourceid} method: post operationId: deleteLockedTag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/delete/resource/{resourceid} method: post operationId: deleteAllTagsByResourceId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/delete/{resourceid} method: post operationId: deleteTag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /assessments/accounts method: get operationId: getAssessmentAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /assessments/accounts method: post operationId: createAssessmentAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /assessments/accounts/{id} method: put operationId: updateAssessmentAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /assessments/accounts/{id} method: delete operationId: deleteAssessmentAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/connector method: get operationId: listCloudConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/connector method: post operationId: createCloudConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/connector/{id} method: get operationId: getCloudConnectorById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/connector/{id} method: delete operationId: deleteCloudConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/policies method: get operationId: getCspmPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/policy/{id}/controls method: get operationId: getCspmPolicyControls x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/control/{controlId}/remediation method: get operationId: getCspmControlRemediation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/report/configuration method: get operationId: getCspmReportConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/report/configuration method: post operationId: createCspmReportConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/report/list method: get operationId: listCspmReports x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/report/run method: post operationId: runCspmReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/report/{id} method: get operationId: getCspmReportById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/report/{id} method: delete operationId: deleteCspmReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cspm/report/{id}/control/{controlId}/resources method: get operationId: getCspmReportControlResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/resources method: get operationId: listCspmResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/resources/{id} method: get operationId: getCspmResourceById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/summary method: get operationId: getCspmSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cspm/usage method: get operationId: getCspmUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vs/asset-vulnerabilities/{coreinstanceid} method: get operationId: getVsAssetVulnerabilities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/asset-vulnerabilities/{coreinstanceid} method: get operationId: getAssetVulnerabilitiesPaged x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/current method: get operationId: getCurrentVulnerabilities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/current/{vulnerabilityReportId} method: get operationId: getCurrentVulnerabilityDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/{scanId}/vms method: get operationId: getVmsByScanId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/{scanId}/vulnerabilities method: get operationId: getVulnerabilitiesByScanId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/vulnerability-scan/{scanId}/vulnerabilities method: get operationId: getVulnerabilitiesWithAssetsCount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/{scanId}/{vulnerabilityReportId} method: get operationId: getVulnerabilityDetailByScanId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/exclusions method: get operationId: listVsExclusions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/exclusions method: post operationId: createVsExclusion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vulnerability-scan/exclusions method: delete operationId: deleteVsExclusion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vulnerability-scan/exclusions/{exclusionId} method: get operationId: getExcludedAssets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/vulnerability-import-scan method: put operationId: generateVulnerabilityReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vulnerability-scan/summary-reports method: get operationId: listVsSummaryReports x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vulnerability-scan/generate-report method: post operationId: generateDetailedVsReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vulnerability-scan/get-export-data method: get operationId: getVsExportData x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts method: get operationId: getAccountDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts method: post operationId: createSubscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/aws-base method: get operationId: getAwsBaseConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connectors method: get operationId: getAllConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connectors method: post operationId: createConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{id} method: get operationId: getConnectorDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connectors/{id} method: delete operationId: deleteConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /images method: get operationId: getAllImages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /images/{id} method: get operationId: getImageDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /registries method: get operationId: getAllRegistries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /registries method: post operationId: createRegistry x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /registries/{id} method: get operationId: getRegistryDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /registries/{id} method: delete operationId: deleteRegistry x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /registries/vendor-types method: get operationId: getVendorTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sensors method: get operationId: getAllSensors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /auth/authorize method: post operationId: authorize x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /auth/token method: post operationId: exchangeToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /auth/token/reissue method: post operationId: refreshToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /me method: get operationId: getCurrentUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /edr/uninstall-code/{cid} method: get operationId: getEdrUninstallCode x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /edr/sign-up method: get operationId: getEdrSignUp x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /edr/sign-up method: post operationId: createEdrSignUp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /edr/configuration method: get operationId: getEdrConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /edr/configuration method: post operationId: createEdrConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /edr/event-forwarder method: get operationId: getEdrEventForwarder x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /edr/usage method: get operationId: getEdrUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-detections/{detectionId}/events method: get operationId: listDetectionEvents x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-detections/{detectionId} method: get operationId: getDetectionDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-detections method: get operationId: listDetections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/security-detections method: get operationId: listDetectionsV2 x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-detections/accounts/{accountId} method: get operationId: listParentCustomerDetections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/security-detections/accounts/{accountId} method: get operationId: listParentCustomerDetectionsV2 x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-detections-overview method: get operationId: getSecurityDetectionsOverview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /trend/av-report method: get operationId: getTrendAvReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-machines method: get operationId: getVirtualMachines x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /operating-systems method: get operationId: getOperatingSystems x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /logs/sources method: get operationId: getLogSources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /logs/sources method: post operationId: createLogSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs/sources/{sourceId} method: delete operationId: deleteLogSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs/sources/{sourceId} method: patch operationId: updateLogSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs/groups method: get operationId: getLogGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /flows/sources method: get operationId: getFlowSources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /flows/sources method: post operationId: createFlowSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /flows/sources/{flowSourceId} method: patch operationId: updateFlowSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /flows/collectors method: get operationId: getFlowCollectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /meta/flows/actions/allocate-flow-source method: post operationId: allocateFlowSource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs/endpoints method: get operationId: getLogEndpoints x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /logs/endpoints/actions/allocate method: post operationId: allocateLogEndpoint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /logs/acls method: get operationId: getLogAcls x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /logs/acls method: post operationId: createLogAcl x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /logs/acls/{aclId} method: put operationId: updateLogAcl x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /meta/logs/sources/actions/check-unique-name method: post operationId: checkHostnameAvailability x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /meta/logs/log-source-types method: get operationId: getLogSourceTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /aip/health method: get operationId: aipHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/health method: get operationId: defenderHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rules/health method: get operationId: rulesHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /incidents/health method: get operationId: jsmHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /report/health method: get operationId: reportsHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ti-middleware/health method: get operationId: tiHealthCheck x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /aip/incident/{incidentKey} method: get operationId: getIncidentAipData x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /aip/incident/{incidentId}/entity/{value} method: get operationId: fetchEntityForIncident x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/machines method: get operationId: getMachines x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/machineactions method: get operationId: getMachineActions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/machineactions/{actionId} method: get operationId: getMachineAction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/machineactions/{machineId} method: post operationId: executeMachineAction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /defender/packageuri/{actionId} method: get operationId: getPackageUri x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /defender/liveresponseresult/{actionId}/{commandId} method: get operationId: getLiveResponseResult x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rules method: get operationId: getRulesForCustomer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /incidents method: get operationId: listIncidents x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /incidents/{issueKey} method: get operationId: getIncidentDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /incidents/{issueKey}/comments method: post operationId: addIncidentComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /incidents/{issueKey}/comment/{commentId} method: get operationId: getCommentAttachments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /metrics/incidents method: get operationId: getIncidentMetrics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /metrics/ti-updates method: get operationId: getThreatIntelUpdates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /metrics/data-ingestion method: get operationId: getDataIngestionMetrics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /service-requests method: get operationId: listServiceRequests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /jsm-orgs/ method: get operationId: getOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /msr/ method: get operationId: listMSRFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /msr/{fileName}/ method: get operationId: getMSRFile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ti/graphql method: post operationId: proxyGraphQL x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ti/threat-actors method: get operationId: getAllThreatActors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ti/threat-actors-by-country method: get operationId: getThreatActorsByCountry x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ti/threat-actors/{threatActorId} method: get operationId: getThreatActorById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ti/customer-ti/ method: get operationId: getCustomerTI x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /preferences/{type} method: get operationId: getUserPreferences x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /preferences/{type} method: put operationId: createOrUpdateUserPreferences x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /preferences/actions/list-for-org method: post operationId: listPreferencesForOrg x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /me method: get operationId: getCurrentUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{entityType}/{entityId}/notes method: get operationId: Notes_GetNoteAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{entityType}/{entityId}/notes method: put operationId: Notes_UpdateNoteAsync x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{entityType}/{entityId}/notes method: delete operationId: Notes_DeleteNoteAsync x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{entityType}/{entityId}/tags method: get operationId: Tags_GetTagsAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{entityType}/{entityId}/tags method: post operationId: Tags_AddTagAsync x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{entityType}/{entityId}/tags method: delete operationId: Tags_DeleteTagAsync x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/activity/history method: get operationId: AccountHistory_GetAccountActivityHistory x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/children method: get operationId: ChildAccounts_GetAllChildAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/children method: post operationId: ChildAccounts_CreateChildAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/children/massgrantaccess method: post operationId: ChildAccounts_MassGrantAccess x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/contacts method: get operationId: AccountContacts_GetContacts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/pricing/{sku} method: get operationId: AccountSkuPricing_GetAccountPrice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/primary-user method: post operationId: PrimaryNotificationUser_UpdateAccountPrimaryBillingContact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts method: get operationId: Accounts_GetAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts method: post operationId: Accounts_UpdateAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{accountId} method: get operationId: Accounts_GetAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/accountusersandrole method: get operationId: Accounts_GetAccountUsersAndRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/primary-billing method: get operationId: AccountPrimaryBilling_GetAccountPrimaryBillingContact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/primary-billing method: put operationId: AccountPrimaryBilling_UpdateAccountPrimaryBillingContact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{accountId}/roles method: get operationId: Accounts_GetRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cloud-connections method: post operationId: CloudConnections_CloudConnections x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cloud-connections/{connectionId} method: get operationId: CloudConnections_CloudConnectionDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cloud-connections/{connectionId} method: delete operationId: CloudConnections_CloudConnection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cloud-connections/connections/isEnabled method: get operationId: CloudConnections_CloudConnectionsEnabled x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cloud-connections/savecloudconnection method: post operationId: CloudConnections_SaveCloudConnectionsDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /cloud-connections/servicetypes method: get operationId: CloudConnections_AllServiceTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cloud-connections/summary method: get operationId: CloudConnections_CloudConnectionsSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /internal/awssecurityhub/audits method: get operationId: InternalAWSSecurityHubAudit_GetAWSSecurityHubAuditsAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /internal/awssecurityhub/audits/{id} method: get operationId: InternalAWSSecurityHubAudit_GetAuditsPayloadByIdAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /invoices method: get operationId: Invoice_GetInvoices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /invoices/{id} method: get operationId: Invoice_GetInvoiceSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /invoices/{id}/detail method: get operationId: Invoice_GetInvoicesDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /paymentmethods method: get operationId: PaymentMethod_GetPaymentMethods x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /paymentmethods/{id} method: delete operationId: PaymentMethod_DeletePaymentMethodById x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /paymentmethods/{id} method: patch operationId: PaymentMethod_SetDefaultPaymentMethod x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /permissions method: get operationId: Roles_GetPermissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /products method: get operationId: ProductCatalog_GetProductLists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /products/{id} method: get operationId: ProductCatalog_GetProductList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /products/{id}/{category} method: get operationId: ProductCatalog_GetProductListByCategory x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /products/{id}/resizeinstance method: get operationId: ProductCatalog_GetResizableInstanceProductList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles method: get operationId: Roles_GetRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles method: post operationId: Roles_CreateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id} method: get operationId: Roles_GetRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles/{id} method: post operationId: Roles_UpdateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id} method: delete operationId: Roles_DeleteRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id}/members/{userId} method: post operationId: Roles_UpdateRoleMember x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{id}/members/{userId} method: delete operationId: Roles_DeleteRoleMember x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /subscriptions method: get operationId: Subscription_GetSubscriptions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /subscriptions/account-details method: get operationId: SubscriptionUsage_GetAllAccountDetailsForPartner x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /subscriptions/account-usage method: get operationId: SubscriptionUsage_GetAccountUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /subscriptions/account-usagedetails method: get operationId: SubscriptionUsage_GetAccountUsageDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /subscriptions/actions/cancel method: post operationId: Subscription_CancelSubscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /subscriptions/hourlyusage method: get operationId: SubscriptionUsage_GetHourlyUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /usage method: get operationId: Usage_GetAccountUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: get operationId: Users_GetUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: post operationId: Users_CreateAccountUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id} method: get operationId: Users_GetUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id} method: put operationId: Users_UpdateUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/keys method: get operationId: Keys_GetApiTokenList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{id}/keys method: put operationId: Keys_RenameAPIKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/keys method: post operationId: Keys_CreateAPIKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/keys/{key} method: delete operationId: Keys_DeleteApiKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{userId}/invite method: post operationId: Users_ResendAccountInvite x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/notifications method: get operationId: Users_GetUserNotificationPreferences x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/notifications method: post operationId: Users_CreateUserNotificationPreferences x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/simpleUserList method: get operationId: Users_GetUsersSimpleList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/status method: post operationId: Users_UpdateUserStatus x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /usersecurity/challengephrase method: put operationId: UserSecurity_UpdateChallengePhrase x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /utilization/{reportType} method: get operationId: Utilization_GetUtilization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /utilization/usage-for method: get operationId: Utilization_GetUsagePerCoreInstance x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{entityType}/{entityId}/tasks method: get operationId: Task_GetList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /{entityType}/{entityId}/tasks method: delete operationId: Task_CancelTask x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /{entityType}/tasks method: get operationId: Task_GetTaskList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apps method: get operationId: App_GetAppList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apps/{appId}/tiers method: get operationId: Tier_GetAppTiers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apps/{appId}/tiers method: post operationId: Tier_AddTier x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/{appId}/tiers/{tierId} method: get operationId: Tier_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apps/{appId}/tiers/{tierId} method: put operationId: Tier_UpdateTier x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/{appId}/tiers/{tierId} method: delete operationId: Tier_DeleteTier x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/{id} method: get operationId: App_GetAppDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apps/{id} method: put operationId: App_UpdateApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/{id} method: delete operationId: App_DeleteApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/vms/{id} method: put operationId: App_AssignVmToWorkLoad x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/activity-logs method: get operationId: AdvancedBackup_GetActivityLogList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/agent-url method: get operationId: AdvancedBackup_GetDownloadRubrikAgentBaseUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/availablelocation method: get operationId: AdvancedBackup_GetActiveRubrikLocations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/externalpolicies method: get operationId: AdvancedBackup_GetExternalSlaDomainList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/fileset/snapshot/{snapshotId}/browse method: get operationId: Fileset_BrowseFilesetFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/fileset/snapshot/{snapshotId}/restore_file method: post operationId: Fileset_RestoreFilesetFiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/filesets method: post operationId: Host_CreateFileSet x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/filesets/{id} method: put operationId: Host_UpdateHostFileSetById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/fileset-template method: get operationId: Host_GetFileSetTemplateList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/fileset-template method: post operationId: Host_CreateFileSetTemplate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/fileset-template/{id} method: get operationId: Host_GetFileSetTemplate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/fileset-template/{id} method: delete operationId: Host_DeleteFileSetTemplate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/fileset-template/{id} method: patch operationId: Host_UpdateFileSetTemplate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/fileset-templates method: get operationId: Host_GetFileSetTemplateNames x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/hosts method: get operationId: Host_GetRubrikHosts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/hosts method: post operationId: Host_AddHost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/hosts/{id} method: delete operationId: Host_DeleteFileSetProtection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/hosts/{id}/filesets method: get operationId: Host_GetFilesetsByHostId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/hosts/{id}/overview method: get operationId: Host_GetFilesetsOverviewByHostId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/hosts/{id}/snapshots method: post operationId: Host_GetFilesetsSnapshotByHostId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/hosts/{id}/syncsnapshots method: post operationId: Host_SyncFilesetSnapshotByHostId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/hosts/fileset/{id} method: delete operationId: Host_RemoveFilesetById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/overview/historicstorageusage method: post operationId: Dashboard_GetAllVmHistoricalPhysicalStorageData x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/overview/vms method: post operationId: Dashboard_GetAllVmsHistoricalOverview x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/policies method: get operationId: AdvancedBackup_GetBackupPoliciesList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/policies method: post operationId: AdvancedBackup_CreateAdvancedBackupPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/policies/{id} method: get operationId: AdvancedBackup_GetBackupPolicyById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/policies/{id} method: delete operationId: AdvancedBackup_DeleteAdvancedBackupPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/policies/{id} method: patch operationId: AdvancedBackup_UpdateBackupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/policies/default method: get operationId: AdvancedBackup_GetDefaultBackupPolicyForAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/policies/types method: get operationId: AdvancedBackup_GetSlaDomainTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/policy/default/{locationId} method: get operationId: AdvancedBackup_GetDefaultPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/unregistered-hosts method: get operationId: Host_GetUnRegisteredRubrikHosts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/vm/{vmId}/policy method: put operationId: AdvancedBackup_UpdateVmPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vm/{vmId}/protected method: get operationId: AdvancedBackup_GetProtectedVmById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/vms/{id}/snapshots method: post operationId: AdvancedBackup_GetVmSnapShots x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/cancelbackuprestore method: post operationId: AdvancedBackup_CancelBackupRestore x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/register-agent method: post operationId: AdvancedBackup_RegisterAgent x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/restoresnapshot method: post operationId: AdvancedBackup_ValidateRestoreVmSnapshotDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/snapshot/{snapshotId}/browse method: get operationId: AdvancedBackup_BrowseFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/vms/{vmId}/snapshot/{snapshotid}/restore_file method: post operationId: AdvancedBackup_RestoreFile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/snapshotrestoreaction method: post operationId: AdvancedBackup_SnapshotRestoreAction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/storage method: get operationId: AdvancedBackup_GetBackupVmStorageDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/vms/{vmId}/storage method: post operationId: AdvancedBackup_UpdateBackupVmStorageDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/{vmId}/syncsnapshots method: post operationId: AdvancedBackup_ExecuteSyncSnapshot x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /backup/vms/services method: get operationId: AdvancedBackup_GetUnprotectedVmsList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /backup/vms/services method: post operationId: AdvancedBackup_AssignVmsToSlaDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/groups method: get operationId: Groups_GetGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/groups method: post operationId: Groups_CreateGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/groups/{id} method: get operationId: Groups_GetGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/groups/{id} method: put operationId: Groups_UpdateGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/groups/{id} method: delete operationId: Groups_DeleteGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/rule method: post operationId: Firewall_CreateIndividualRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/rule/{ruleId} method: get operationId: Firewall_GetFirewallRuleById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/rule/{ruleId} method: put operationId: Firewall_UpdateIndividualRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/rules method: get operationId: Firewall_GetRuleSet x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/rules/export method: get operationId: Firewall_GetFirewallRuleCsvExport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/services method: get operationId: Services_GetServices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/services method: post operationId: Services_CreateService x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/services/{serviceGroupId} method: get operationId: Services_GetService x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /firewall/{ovdcId}/services/{serviceGroupId} method: put operationId: Services_UpdateService x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/{ovdcId}/services/{serviceGroupId} method: delete operationId: Services_DeleteService x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewall/rules/{ruleId} method: put operationId: Firewall_EnableDisableFirewallRule x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /firewall/rules/{ruleId} method: delete operationId: Firewall_DeleteRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /firewalls method: get operationId: Firewall_GetFirewalls x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /health-monitoring/core/health/{vmId} method: get operationId: ServiceHealth_HealthStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /health-monitoring/core/health-status/{vmId} method: get operationId: ServiceHealth_HealthStatusPublic x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ips method: get operationId: Ip_GetIps x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ips method: post operationId: Ip_AssignPrivateIpToVm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ips method: delete operationId: Ip_UnAssignIpFromVm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ips/publicIps/quantity/{quantity} method: post operationId: Ip_AssignExtDnatToAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /l2l method: get operationId: L2L_GetL2LList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /l2l method: post operationId: L2L_CreateL2L x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /l2l/{id} method: get operationId: L2L_GetL2L x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /l2l/{id} method: delete operationId: L2L_DeleteL2L x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /l2l/{id}/esglimit/check method: get operationId: L2L_CheckEsgLimit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /locations method: get operationId: Location_Get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /nats method: get operationId: Nat_GetNatRules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /nats method: put operationId: Nat_UpdateNatRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /nats method: post operationId: Nat_AddNatRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /nats method: delete operationId: Nat_DeleteNatRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /nats/vm/{vmId} method: get operationId: Nat_GetNatRulesByVmId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orders method: get operationId: Orders_GetOrdersAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orders/{id} method: get operationId: Orders_GetOrderAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orders/{osname}/wsus method: get operationId: Orders_GetWsusDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orders/subscriptions method: post operationId: Orders_PostSubscriptionOrderAsync x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orders/vms method: post operationId: Orders_PostVmOrderAsync x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ssl-certificates method: get operationId: SslCertificates_GetSslCertificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ssl-certificates/{id} method: put operationId: SslCertificates_UpdateSslCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /ssl-certificates/{id} method: delete operationId: SslCertificates_CancelSslCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /sslvpn method: get operationId: SslVpn_GetSslVpnList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sslvpn/client-config method: get operationId: SslVpn_GetSslVpnConfigDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sslvpn/enable method: post operationId: SslVpn_EnableSslVpn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /sslvpn/members method: get operationId: SslVpn_GetSslVpnMembers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /stats/vms/{vmId} method: get operationId: Stats_GetAllUtilizationStats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /stats/vms/{vmId}/metrics method: get operationId: Stats_GetAllStatusForOneVm x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /storage/summary method: get operationId: Storage_GetStorageSummaryByAccountId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms method: get operationId: Vm_GetVmList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/{id} method: get operationId: Vm_GetVmDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/{id} method: put operationId: Vm_UpdateVm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{id} method: delete operationId: Vm_DeleteVm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{id}/adjustResources method: post operationId: Vm_AdjustVmResources x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{id}/license method: get operationId: Vm_GetLicenseDetailsByVmId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/{id}/power/{powerAction} method: post operationId: Vm_PowerActionVm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{id}/processScheduledEvent method: post operationId: Vm_ProcessScheduledEvent x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{vmId}/availableStorage method: get operationId: Storage_GetAvailableStorageByVm x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/{vmId}/disk method: post operationId: Storage_AddDisk x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{vmId}/disk/{diskId} method: delete operationId: Storage_DeleteDisk x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/{vmId}/disk/{diskId}/advancedsettings method: put operationId: Storage_UpdateDiskAdvancedSettings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/autoAgePolicy method: get operationId: Vm_GetAccountAutoAgePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/autoAgePolicy method: post operationId: Vm_UpsertAccountAgePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/core/{coreInstanceId} method: get operationId: Vm_GetVmCoreDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/core/{coreInstanceId} method: delete operationId: Vm_DeleteCore x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/core/{coreInstanceId}/profile method: put operationId: Vm_AssignCoreInstanceProfileByName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vms/hybridVmList method: get operationId: Vm_GetVmListWithCloudConnections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/os-endoflife method: get operationId: Vm_GetVmOSEndOfLife x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/simpleVmList method: get operationId: Vm_GetAllVmList x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vms/unprotectedec2instance/{id} method: get operationId: Vm_GetUnprotectedEc2InstanceDetailById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/{coreinstanceId}/security method: get operationId: Trend_GetCoreInstanceTrendSecurityDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/avam method: get operationId: Trend_GetAvamScanResults x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/avam/statistics method: get operationId: Trend_GetAvamOverAllStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/fim method: get operationId: Trend_GetFimResults x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/fim/statistics method: get operationId: Trend_GetFimOverAllStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/manual-scan/{coreInstance}/start method: post operationId: TrendManualScan_StartManualScan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /core/manual-scan/getCurrentAndPastScan method: get operationId: TrendManualScan_GetCurrentAndPastScan x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/packages/{coreInstanceId} method: get operationId: Packages_GetDevicePackages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/packages/status method: get operationId: Packages_GetStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/security-dashboard/stats/overall method: get operationId: Trend_GetSecurityDashboardOverAllStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/security-dashboard/stats/overview method: get operationId: Trend_GetSecurityDashboardStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /core/trend-sync/{coreInstanceId} method: get operationId: Trend_GetTrendSyncDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management method: get operationId: VmLog_VmLogDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/log-depot/activate method: post operationId: VmLog_ActivateLogDepot x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-management/log-depot/deactivate method: post operationId: VmLog_DeactivateLogDepot x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-management/logretentiontypes method: get operationId: AccountLogRetention_LogRetentionTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/logsources method: get operationId: LogSource_LogSourceDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/logsources/connector-request method: post operationId: LogSource_RequestConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-management/logsources/log-insight/notification method: get operationId: LogSource_DisplayLogInsightNotification x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/logsources/log-insight/notification method: post operationId: LogSource_UpdateLogInsightNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-management/logsources/loginsight-overview method: get operationId: LogSource_LogInsightOverview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/log-storage method: get operationId: AccountLogRetention_GetLogStorageUtilized x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/log-storage-totals method: get operationId: AccountLogRetention_GetLogUtilizationTotals x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/products/{id} method: get operationId: VmLog_GetServiceTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-management/retentionplan method: post operationId: VmLog_UpgradeLogRetentionPlan x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /log-management/update-logretentionplan method: post operationId: AccountLogRetention_UpgradeRetentionPlan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-management/vms/{coreInstanceId} method: get operationId: VmLog_GetVmLogStats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /log-search/templatedsearch method: post operationId: LogSearch_GetLogs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /log-search/templatedsearch/deprecated method: post operationId: LogSearch_GetLogsDeprecated x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security-analytics/active-response method: get operationId: ActiveResponse_GetActiveResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-analytics/overview method: get operationId: SecurityAnalytics_SecurityAnalyticsOverview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-analytics/resources method: get operationId: SecurityResource_GetSecurityResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-incidents method: get operationId: SecurityIncidents_GetSecurityIncidents x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security-incidents/severity-count method: get operationId: SecurityIncidents_GetSecurityIncidentsSeverityCount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /stats/security/time-series method: get operationId: TimeSeries_GetDataPointsAsync x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/{issueKeyId}/comments method: get operationId: Tickets_GetTicketComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/{issueKeyId}/comments method: post operationId: Tickets_CreateTicketComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tickets/{issueKeyId}/details method: get operationId: Tickets_GetIssueDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/{issueKeyId}/transition method: get operationId: Tickets_GetAvailableIssueStatuses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/{issueKeyId}/transition method: post operationId: Tickets_TransitionIssueStatus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tickets/{ticketNumber} method: get operationId: Tickets_GetTicket x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/{ticketNumber}/attachments method: get operationId: Tickets_GetAttachment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/count method: get operationId: Tickets_GetPagedTicketsCount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/entries method: get operationId: Tickets_GetPagedTickets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/groups method: get operationId: Tickets_GetTicketGroupsByAccountId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/groups/{id}/member/{userId} method: delete operationId: Tickets_RemoveTicketGroupMember x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tickets/groups/{id}/members method: get operationId: Tickets_GetTicketsGroupMembers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/groups/member method: post operationId: Tickets_AddTicketGroupMember x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tickets/list method: get operationId: Tickets_GetIssuesForAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/list-all method: get operationId: Tickets_GetAllIssuesForAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/members/groups method: get operationId: Tickets_GetTicketGroupsByUserId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/meta-data method: get operationId: Tickets_GetTicketsMetaData x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tickets/users method: get operationId: Tickets_GetUsersWithTicketingPermissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/detection method: get operationId: getDetectionConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/detection method: post operationId: createDetectionConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security/detection/{detection_id} method: post operationId: updateDetectionConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security/detection/delete/{detection_id} method: post operationId: deleteDetectionConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security/detection/event-type method: get operationId: getEventTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/notification method: get operationId: getNotificationConfigurations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/notification method: post operationId: createNotificationConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security/notification/{notification_id} method: get operationId: getNotificationConfigurationById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/notification/{notification_id} method: post operationId: updateNotificationConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /security/notification/delete/{notification_id} method: post operationId: deleteNotificationConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required